A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
History

Fri, 25 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2018-07-16T20:00:00

Updated: 2024-10-25T14:08:48.618Z

Reserved: 2017-12-11T00:00:00

Link: CVE-2017-17541

cve-icon Vulnrichment

Updated: 2024-08-05T20:51:32.239Z

cve-icon NVD

Status : Analyzed

Published: 2018-07-16T20:29:00.270

Modified: 2018-09-12T19:22:27.007

Link: CVE-2017-17541

cve-icon Redhat

No data.